CVE-2026-28114 PUBLISHED

WordPress WooCommerce License Manager plugin <= 7.0.6 - Arbitrary File Upload vulnerability

Assigner: Patchstack
Reserved: 25.02.2026 Published: 05.03.2026 Updated: 05.03.2026

Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.

Product Status

Vendor firassaidi
Product WooCommerce License Manager
Versions Default: unaffected
  • affected from n/a to <= 7.0.6 (incl.)

Credits

  • Bonds | Patchstack Bug Bounty Program finder

References

Problem Types

  • Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • Upload a Web Shell to a Web Server